Metabase SQLi exploit grants attackers total access

Summary

Business intelligence platform Metabase has disclosed a critical zero-day SQL injection vulnerability, CVE-2026-72898, affecting versions 1.58 and up. Attackers can exploit this flaw to gain unmitigated access to sensitive data within the Metabase database, including credentials and tokens. Metabase has patched the vulnerability and urges self-hosted customers to apply the update.

IFF Assessment

FOE

The discovery of a critical zero-day SQL injection vulnerability with a perfect CVSS score signifies a major security risk that could lead to widespread data compromise.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 14, 2026. Known ransomware use: Unknown.

Defender Context

This critical SQL injection vulnerability in Metabase presents a significant risk to organizations utilizing the platform for business intelligence. Defenders must prioritize patching self-hosted instances immediately and audit for any signs of compromise. The exploit's ease of use and the sensitive data it can expose make it a prime target for attackers.

Read Full Story →